Netskope Threat Labs

Vawtrak

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Vawtrak (a.k.a. NeverQuest) is a banking trojan, and Spanish authorities arrested its operator in 2017 after the FBI placed him on its wanted list. The family later resurfaced as Bokbot, and its code lineage connects it to other banking malware through shared developers and overlapping infrastructure.

First seen
April 2022
Last seen
September 2026
VawTrak
Alert Name
Document-Word.Backdoor.Vawtrak
Gen:Variant.VawTrak.1
Win32.Backdoor.Vawtrak